Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10391

Опубликовано: 11 мая 2026
Источник: fstec
CVSS3: 5.5
CVSS2: 4.9
EPSS Низкий

Описание

Уязвимость утилиты для обработки JSON-файлов jq связана с непринятием мер по нейтрализации нулевого байта или символа NUL. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании

Вендор

Canonical Ltd.
Red Hat Inc.
Сообщество свободного программного обеспечения
ООО «Ред Софт»
Stephen Dolan

Наименование ПО

Ubuntu
Red Hat Enterprise Linux
Red Hat Ceph Storage
Debian GNU/Linux
РЕД ОС
Red Hat OpenShift Container Platform
Ansible Automation Platform
Red Hat Hardened Images
jq

Версия ПО

14.04 LTS (Ubuntu)
18.04 LTS (Ubuntu)
8 (Red Hat Enterprise Linux)
20.04 LTS (Ubuntu)
4 (Red Hat Ceph Storage)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
4 (Red Hat OpenShift Container Platform)
22.04 LTS (Ubuntu)
9 (Red Hat Enterprise Linux)
24.04 LTS (Ubuntu)
10 (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
2 (Ansible Automation Platform)
- (Red Hat Hardened Images)
26.04 LTS (Ubuntu)
до 1.8.2 (jq)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Canonical Ltd. Ubuntu 14.04 LTS
Canonical Ltd. Ubuntu 18.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 8
Canonical Ltd. Ubuntu 20.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Canonical Ltd. Ubuntu 22.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 9
Canonical Ltd. Ubuntu 24.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 10
ООО «Ред Софт» РЕД ОС 8.0
Canonical Ltd. Ubuntu 26.04 LTS

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,9)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,5)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-41256
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-41256
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-41256
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-41256

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 5%
0.00158
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
redos
23 дня назад

Уязвимость jq

CVSS3: 5.5
ubuntu
3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.

CVSS3: 5.5
redhat
3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.

CVSS3: 5.5
nvd
3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.

CVSS3: 5.5
msrc
3 месяца назад

jq: Embedded NUL truncates top-level jq programs loaded with -f

EPSS

Процентиль: 5%
0.00158
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2